Lightweight multi-agent TUI and stable cross-provider collaboration layer for Codex, Claude, Gemini, Grok, Kimi, and other CLI agents.
No concrete attack was identified. The postinstall downloads and bootstraps the package's own versioned CLI release.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/ask.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-runner.jsView on unpkgThis report applies to @seemseam/ccb@8.7.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L54Package source references dynamic require/import behavior.
bin/ask.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-runner.jsView on unpkg